nerdexam
Isaca

CRISC · Question #17

An organization has decided to use an external auditor to review the control environment of an outsourced service provider. The BEST control criteria to evaluate the provider would be based on:

The correct answer is D. The organization's specific control requirements. When auditing an outsourced service provider's control environment, the best criteria are the specific control requirements of the organization utilizing the service.

Submitted by obi.ng· Apr 18, 2026Governance

Question

An organization has decided to use an external auditor to review the control environment of an outsourced service provider. The BEST control criteria to evaluate the provider would be based on:

Options

  • Aa recognized industry control framework
  • Bguidance provided by the external auditor
  • Cthe service provider's existing controls
  • DThe organization's specific control requirements

How the community answered

(27 responses)
  • A
    19% (5)
  • B
    7% (2)
  • C
    4% (1)
  • D
    70% (19)

Why each option

When auditing an outsourced service provider's control environment, the best criteria are the specific control requirements of the organization utilizing the service.

Aa recognized industry control framework

While a recognized industry control framework provides a good baseline, it may not fully encompass the specific risks, regulatory requirements, or business objectives unique to the client organization.

Bguidance provided by the external auditor

Guidance provided by the external auditor might reflect best practices but should not be the sole basis for control criteria; the auditor's role is to assess against established criteria, not to unilaterally define them for the client.

Cthe service provider's existing controls

The service provider's existing controls define their current state but may not align with the client organization's specific security posture, risk appetite, or compliance mandates, thus not being the best criteria for evaluation.

DThe organization's specific control requirementsCorrect

The organization's specific control requirements are the BEST criteria because the primary purpose of auditing an outsourced service provider is to ensure that the provider's controls adequately protect the client organization's assets and meet its risk tolerance and compliance obligations. While industry frameworks can inform these requirements, the client's unique business context and regulatory needs dictate what truly constitutes effective control.

Concept tested: Third-Party Risk Assessment Criteria

Source: https://nvlpubs.nist.gov/nistpubs/specialpublications/nist.sp.800-53r5.pdf

Topics

#Outsourced services risk#Control evaluation criteria#Vendor risk management#Organizational accountability

Community Discussion

No community discussion yet for this question.

Full CRISC Practice